RE: How do I send EDI file securely over Internet?

"Bob Atkinson" <[email protected]> Mon, 3 Jun 2002 11:57:42 -0700
Newsgroups gmane.ietf.ediint
Message-ID <F7CB5F0CAA300344964AC7D2BE43081F015DBD94@DF-MAX.platinum.corp.microsoft.com>
Perhaps you have the wrong Bob. I apologize, but I don't recall working
on RFC1767, nor have I worked for the government.

	Bob

-----Original Message-----
From: Dick Brooks [mailto:[email protected]] 
Sent: Monday, June 03, 2002 9:58 AM
To: Robert E. Frank; Dick Brooks; Rishel,Wes; [email protected]
Subject: RE: How do I send EDI file securely over Internet?


Hello Bob,

It's been quite awhile since we last communicated (1992 I believe). I
was
working at DEC and I believe you were working for the Government at one
of
the National Labs (was it Sandia?). I recall we were both working with
Dave
Crocker on what eventually became RFC 1767. We've been at this a long
time...

I find it troubling to see such deep division within the EDIINT
workgroup.
We continue to experience skirmishes over SMTP and HTTP, S/MIME and
OpenPGP.
I also expect a confrontation to breakout within the AS2 camp over the
two
available packaging options, RFC2388 compliant versus the AS2 specific
email
like packaging with AS2-To and AS2-From extension headers (as synonyms
for
the RFC 822 To and From headers) at the HTTP level to identify
sender/recipient.

Now, we have a fairly well defined reliable, secure ebXML Message
Service
(supported by DISA and UN/CEFACT) that, IMO, is a more cohesive, elegant
and
better engineered framework for E-Commerce than either AS1 or AS2.
ebXML's
Message Service is built on SOAP and supports a full range of web
services
functionality as well as the standard EDI transport function.

Also, let's not forget the imminent competition coming from some of the
other alternatives, such as WS-Security [1] (Microsoft) and HTTPR [2]
(IBM).

IMO, competition between these various "standards" is creating a
difficult
situation for implementers. A recent letter from Tim Thomasma of Ford
Motor
Company and Co-Chair, XML/EDI Work Group, Automotive Industry Action
Group,
to David Berlind at Cnet.com sums it up better than I, he states:


"The last thing we need is some sort of new "Sun + allies / ebXML" vs.
"Microsoft + allies / Web services" technology war. Competition is
wonderful, but can each vendor please implement reliable, secure XML
messaging over HTTP in such a way that it interoperates with everyone
else's
implementation?"

In closing, I refer you to an article I wrote describing E-Commerce
standardization in the Energy industry that expresses concerns similar
to
those expressed by Tim, ref:

"The Struggle for B2B Standards: A Tale of e-Commerce Standardization in
the
Energy Industry"
http://b2b.ebizq.net/std/brooks_1.html

Tim, if you're listening - good letter.

[1]
http://msdn.microsoft.com/library/default.asp?url=/library/en-us/dnglobs
pec/
html/wssecurspecindex.asp

[2] http://www-106.ibm.com/developerworks/webservices/library/ws-phtt/

Dick Brooks
Systrends, Inc
7855 South River Parkway, Suite 111
Tempe, Arizona 85284
Web: www.systrends.com <http://www.systrends.com>
Phone:480.756.6777,Mobile:205-790-1542,eFax:240-352-0714